Skip to content

manage.flexfs

manage.flexfs provides optional host-level management of flexFS systemd services and the binaries in /sbin. Most subcommands require root privileges; init creds, deinit creds, deploy, license, and version do not. FlexFS servers and mount clients do not need manage.flexfs or root to run.

These flags apply to every subcommand.

FlagTypeDefaultDescriptionVisibility
--reportErrorsboolfalseReport errors and panics to Paradigm4Public
SubcommandDescriptionVisibility
cleanRemove downloaded flexFS binaries from /tmpPublic
deinit credsRemove credentials filePublic
deployDeploy mount.flexfs binary to staging/production channelsPublic
download [binary...]Download flexFS binaries to /tmpPublic
init credsInitialize credentials (custom download server address)Public
install [binary...]Install flexFS binaries from /tmp to /sbinPublic
licensePrint license informationPublic
restart [service...]Restart services (stop, start)Public
start [service...]Start flexFS systemd servicesPublic
status [service...]Show status of flexFS servicesPublic
stop [service...]Stop flexFS systemd services (reverse order)Public
upgrade [binary...]Full upgrade cycle (clean, download, install, restart affected services)Public
versionPrint the build versionPublic
watch <service>Follow journal logs for a flexFS servicePublic

When a service argument is omitted, all services are targeted. The available service names are:

ServiceBinaryStart Order
errorerror.flexfs1
statstat.flexfs2
awsaws.flexfs3
adminadmin.flexfs4
freefree.flexfs5
proxyproxy.flexfs6
metameta.flexfs7

Services are started in the order shown above and stopped in reverse order. Services whose systemd unit is not installed are skipped.

The download, install, deploy, and upgrade subcommands take a --version that is either an exact release (e.g. v1.9.1) or a version line (e.g. v1.9.x), which resolves to the newest release on that line. When --version is omitted, the version line of the running manage.flexfs build is used. A build that carries no version (a development build) stops with build version is unversioned; please specify --version.

The --vacuum flag rotates the systemd journal and then deletes every archived journal file (journalctl --rotate followed by journalctl --vacuum-time=1s). This removes the past logs of every service on the host, not only flexFS services.

Terminal window
manage.flexfs init creds --downloadAddr <download-addr> [--credsFile <path>] [--force]

Initializes a credentials file for manage.flexfs with a custom download server address. Commands that download binaries (download, deploy, upgrade, install) read this file to resolve the server address, by default from the home folder of the user running them. download, install, and upgrade run as root and read root’s file (/root/.flexfs/manage/creds), so run init creds with sudo for them. deploy run as another user reads that user’s file. init on its own does the same thing as init creds.

FlagTypeDefaultDescriptionVisibility
--credsFilestring~/.flexfs/manage/credsCredentials file path to writePublic
--downloadAddrstring""Download server address (required)Public
--forceboolfalseOverwrite existing credentials filePublic
Terminal window
manage.flexfs deinit creds [--credsFile <path>]

Removes the credentials file. After removal, download commands fall back to the default server (get.flexfs.io).

FlagTypeDefaultDescriptionVisibility
--credsFilestring~/.flexfs/manage/credsCredentials file pathPublic
Terminal window
sudo manage.flexfs start [--vacuum] [service...]

Starts the specified flexFS systemd services. If no services are named, all installed services are started.

FlagTypeDefaultDescriptionVisibility
--vacuumboolfalseAlso vacuum system journal logs (see Journal vacuuming)Public
Terminal window
sudo manage.flexfs stop [--vacuum] [service...]

Stops the specified services in reverse order to respect dependencies.

FlagTypeDefaultDescriptionVisibility
--vacuumboolfalseAlso vacuum system journal logs (see Journal vacuuming)Public
Terminal window
sudo manage.flexfs restart [--vacuum] [service...]

Stops and starts the specified services.

FlagTypeDefaultDescriptionVisibility
--vacuumboolfalseAlso vacuum system journal logs (see Journal vacuuming)Public
Terminal window
sudo manage.flexfs status [service...]

Shows the active state and uptime of each installed service.

Terminal window
sudo manage.flexfs clean [--vacuum]

Removes flexFS temporary files (/tmp/*.flexfs). Optionally vacuums systemd journal logs.

FlagTypeDefaultDescriptionVisibility
--vacuumboolfalseAlso vacuum system journal logs (see Journal vacuuming)Public
Terminal window
sudo manage.flexfs download [--version <ver>] [--arch <arch>] [--install] [binary...]

Downloads the specified flexFS binaries to /tmp, after first removing any /tmp/*.flexfs files. With no binary names, it downloads the binaries already installed in /sbin. Uses the download server address from the credentials file, or get.flexfs.io by default.

FlagTypeDefaultDescriptionVisibility
--archstringhost architectureArchitecture to download (e.g. amd64, aarch64)Public
--credsFilestring~/.flexfs/manage/credsCredentials file pathPublic
--downloadAddrstring""Download server address (overrides credentials file)Internal
--installboolfalseInstall binaries to /sbin after downloadingPublic
--versionstringbuild’s version lineVersion or version branch to download (e.g. v1.9.1, v1.9.x)Public
Terminal window
sudo manage.flexfs install [--version <ver>] [--arch <arch>] [binary...]

Installs flexFS binaries from /tmp to /sbin. A file in /tmp is installed only if it is a regular, single-link file owned by root and not writable by group or others. When binary names are given, only those are installed, and any that are missing from /tmp or do not qualify are downloaded first. Without names, every qualifying flexFS binary in /tmp is installed and files that do not qualify are skipped. Each binary replaces the installed one in a single step, and its SELinux label is restored from policy with restorecon when available, or set to bin_t with chcon otherwise. install also removes /sbin/update.flexfs if present.

FlagTypeDefaultDescriptionVisibility
--archstringhost architectureArchitecture to download for missing binariesPublic
--credsFilestring~/.flexfs/manage/credsCredentials file path (used when downloading missing binaries)Public
--downloadAddrstring""Download server address (overrides credentials file)Internal
--versionstringbuild’s version lineVersion or version branch for missing binaries (e.g. v1.9.1, v1.9.x)Public
Terminal window
manage.flexfs deploy [--channel <channel>] [--version <ver>] [--adminPath <path>]

Downloads mount.flexfs for both architectures and places them in the deploy folder under --adminPath, from which the admin server serves mount client installs and auto-updates.

deploy does not require root. Run it as the user that runs the admin server, or as any user that can write to --adminPath. When run as root, it gives the deploy folder, its channel folders, and each version it deploys the owner and group of --adminPath, so an admin server that runs as another user can read them.

deploy does nothing on a host without an admin server, such as a Community installation. If --adminPath contains neither the admin database (db) nor the admin credentials file (creds), it prints No admin server found in <path>; nothing to deploy and exits successfully without downloading anything. When --adminPath is given explicitly and holds neither file, deploy exits with an error instead.

FlagTypeDefaultDescriptionVisibility
--adminPathstring~/.flexfs/adminAdmin folder path, in the home folder of the user running the commandPublic
--channelstringallDeployment channel: staging, production, or allPublic
--credsFilestring~/.flexfs/manage/credsCredentials file pathPublic
--downloadAddrstring""Download server address (overrides credentials file)Internal
--versionstringbuild’s version lineVersion or version branch to deploy (e.g. v1.9.1, v1.9.x)Public
Terminal window
sudo manage.flexfs upgrade [--version <ver>] [--arch <arch>] [--vacuum] [--deploy [--channel <channel>] [--adminPath <path>]] [binary...]

Performs a full upgrade: cleans state, downloads and installs binaries, then restarts only the services whose binaries were upgraded (not all services). When no binary names are given, it upgrades every flexFS binary found in /sbin. With --deploy, it then deploys mount.flexfs for the upgraded version — equivalent to running deploy afterward, reusing the same --version. On a host without an admin server, the deploy step does nothing and the upgrade still succeeds.

FlagTypeDefaultDescriptionVisibility
--adminPathstring~/.flexfs/adminAdmin folder path (used with --deploy)Public
--archstringhost architectureArchitecture to downloadPublic
--channelstringallDeployment channel for --deploy: staging, production, or allPublic
--credsFilestring~/.flexfs/manage/credsCredentials file pathPublic
--deployboolfalseAfter upgrading, also deploy mount.flexfs (equivalent to running deploy)Public
--downloadAddrstring""Download server address (overrides credentials file)Internal
--vacuumboolfalseAlso vacuum system journal logs (see Journal vacuuming)Public
--versionstringbuild’s version lineVersion or version branch to download (and deploy with --deploy)Public
Terminal window
sudo manage.flexfs watch [--lines <n>] [--cat] <service>

Follows journal logs for a flexFS service using journalctl -f.

FlagTypeDefaultDescriptionVisibility
--catboolfalseUse plain text output (journalctl -o cat)Public
--linesint100Number of recent log lines to showPublic